import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;

public class Test1 {

	public static void main(String[] args) {
			//第一步: 加载驱动程序
		try {
			Class.forName("com.mysql.jdbc.Driver");
			//第二步: 弄一个驱动程序
		String url  = "jdbc:mysql://localhost:3306/stu?useUnicode=true&characterEncoding=utf8";
		String user = "root";
		String pass = "123456";
		Connection con = DriverManager.getConnection(url, user, pass);
		//Statement st = con.createStatement();
		//ResultSet rs = st.executeQuery("select * from student1 where sage>20 and ssex='女'");
			
		//先用prepareStatement执行sql语句,用"?"代替参数
		//如果参数为int类型,那么就是ps.setInt;
		//如果参数为string类型,那么就是ps.setString;
PreparedStatement ps = con.prepareStatement("select * from student1 where sage>? and ssex=?");
			ps.setInt(1, 20);
			ps.setString(2, "女");
			ResultSet rs = ps.executeQuery();
			while(rs.next()) {
				System.out.println("学号:"+rs.getString("sno")+
							     ",院系:"+rs.getString("sdep")+
							     ",性别:"+rs.getString("ssex")+
							     ",年龄:"+rs.getString("sage")+
							     ",姓名:"+rs.getString("sname"));
			}
			rs.close();
			//st.close();
			ps.close();
			con.close();
		} catch (ClassNotFoundException e) {
			
			e.printStackTrace();
		} catch (SQLException e) {
			
			e.printStackTrace();
		}

	}

}
